ProfitCollector MCP server
22 pay-per-call developer, security, network and data utilities using x402 on Base.
Little public usage data yet
Reviews
Write oneNobody has reviewed ProfitCollector yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
ProfitCollector tools (31, 20 write)
write = sends, deletes, buys or postsget_dns_lookupFreeResolve ONE DNS record type for a domain. For all record types at once use /domain/intelligence; for a bundled DNS+TLS+headers audit use /web/audit or /security/posture; for mail-security plus a scored verdict use /domain/due-diligence.
get_domain_intelligenceFreeCollect ALL common DNS record types (A/AAAA/MX/NS/TXT/CAA) for a domain in one call -- the multi-record bundle version of /dns/lookup.
get_jwt_decodeFreeDecode a JWT payload without signature verification.
get_security_headersFreeInspect HTTP security headers for ONE URL only. For headers combined with TLS and DNS, use /web/audit (raw) or /security/posture (scored).
get_security_postureFreeAssess TLS and HTTP security posture for a public HTTPS website -- the SAME inspection as /web/audit, but returns a 0-100 score/grade and findings instead of raw fields.
get_ssl_checkFreeInspect the TLS certificate for ONE hostname only. For TLS combined with HTTP headers and DNS, use /web/audit (raw) or /security/posture (scored).
get_subnet_calculateFreeCalculate subnet information from CIDR notation.
get_timestamp_convertFreeConvert a Unix timestamp to UTC ISO-8601.
get_url_parseFreeParse a URL into structured components.
get_uuid_generateFreeGenerate a random UUID version 4.
get_web_auditFreeConsolidated DNS, TLS and HTTP security audit for a public HTTPS website, returned as RAW findings (no score) -- the bundled version of /dns/lookup + /ssl/check + /security/headers. Use /security/posture instead for a 0-100 score/grade.
post_base64_decodewrite actionFreeDecode Base64 to UTF-8 text.
post_base64_encodewrite actionFreeEncode UTF-8 text using Base64.
post_data_transformwrite actionFreeNormalize and transform common structured text automatically.
post_domain_due_diligencewrite actionFreeThe most comprehensive domain assessment: DNS + mail security (SPF/DKIM/DMARC) + TLS + HTTP headers, scored. The only endpoint in this group that adds mail-security analysis. Use for a one-shot decision-grade verdict on an unfamiliar domain; use /dns/lookup, /ssl/check, /security/headers, /web/audit or /security/posture instead for a single fact or a cheaper signal.
post_freshdep_scanwrite actionFreeFlags pinned dependencies in a repository's requirements.txt, package-lock.json, or uv.lock published more recently than a freshness threshold -- a supply-chain-compromise tripwire. Free CLI (requirements.txt/package-lock.json only, uv.lock support pending there): github.com/sbakhour/freshdep.
post_hash_sha256write actionFreeGenerate SHA-256 digest from text.
post_hash_sha512write actionFreeGenerate SHA-512 digest from text.
post_json_minifywrite actionFreeMinify valid JSON text.
post_json_prettywrite actionFreePretty-print valid JSON text.
post_json_repairwrite actionFreeRepair common malformed JSON formatting issues.
post_json_validatewrite actionFreeValidate JSON text and return parsing details.
post_media_image_convertwrite actionFreeConvert an image between common formats (e.g. PNG/JPEG/WebP) from a URL or base64 payload.
post_quebec_invoice_compliance_checkwrite actionFreeVerifies GST/QST were calculated correctly per Revenu Quebec's current (non-compounded) formula, and flags whether a French invoice version is present per Charter of the French Language s.57/89/91. Pure arithmetic + text check; not legal or tax advice.
post_quebec_invoice_generatewrite actionFreeAssembles a bilingual (French/English) Quebec invoice document with GST/QST computed exactly per Revenu Quebec's current formula -- you supply both languages' line-item text, this does not translate. Not legal or tax advice.
post_security_repo_risk_report_deepwrite actionFreeEverything in the standard report, plus a repo-wide secret/credential exposure scan (matched values are never returned).
post_security_repo_risk_report_due_diligencewrite actionFreeEverything in the deep report, plus real OpenSSF Scorecard maintainer/governance signals and a prioritized recommendation. An automated baseline positioned against $5,000-$95,000 human technical due diligence.
post_security_repo_risk_report_standardwrite actionFreeSBOM inventory plus real OSV.dev dependency-vulnerability matches and dependency-freshness signals for a public Git repository. One-shot alternative to a per-seat secret-scanning subscription.
post_text_dedupe_lineswrite actionFreeRemove duplicate lines while preserving original order.
post_text_statswrite actionFreeCalculate character, word, line and byte statistics.
post_x402_service_trust_reportwrite actionFreeLive, on-demand check of ONE x402-protected endpoint before you pay it: payment-requirements structure, TLS certificate, payTo on-chain balance, known-asset recognition, resource/host consistency, and discovery-manifest cross-check -- not a cached aggregate reputation score.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 995ms20/20
- Tool poisoning31 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 20 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http profitcollector https://mcp.bakhour.ca/mcp
ProfitCollector: common questions
- Is ProfitCollector MCP server safe?
- With care: it is graded C, so read the findings first (60/100). Read the ProfitCollector safety report
- How do I install ProfitCollector?
- It runs remotely at mcp.bakhour.ca. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does ProfitCollector need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is ProfitCollector maintained?
- The latest release is v1.0.0.
- Is ProfitCollector up?
- 100% of our last 7 checks got an answer. We check remote servers about four times a day.
- What can I use instead of ProfitCollector?
- Servers from other publishers that do the same job: AARF Utility Network MCP server, signals.edge graduation radar MCP server and Avanan MSP (Legacy SmartAPI) MCP server. Compare all ProfitCollector alternatives.
Alternatives to ProfitCollector
Same job from other publishers: the closest match first, then the best rated.
AARF Utility NetworkPaid AI utilities for web comparison, code checks, document extraction, security, and research.not reviewedNewC- signals.edge graduation radarpump.fun graduation radar for trading bots and AI agents. x402 USDC per scan, no key.not reviewedGrowingA
- Avanan MSP (Legacy SmartAPI)MCP server for the legacy Avanan SmartAPI: MSP tenant management plus per-tenant security tools.not reviewedNewB
- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB